7 ms·
I'm confused about if this means that IndexedDB will always wipe data after 7 days. That seems like it would prevent storage from being used for user data in PW
by pspeter3 7y ago
I'm confused about if this means that IndexedDB will always wipe data after 7 days. That seems like it would prevent storage from being used for user data in PWAs.
- jessaustin 7y agoWow they buried the lede; I'm glad you highlighted this. This is going to be an interesting situation for some Safari users. "Why did your app delete my data?" "If you don't like that you should use Chrome." Of course Google could do this too, if they had a reason, even if only downstream from Chromium. It's just a commercial decision. Apple have decided they don't want their users to have usable anonymous web apps. Of course, since they don't support beforeinstallprompt, we already know they don't want their users to have web apps, period. Gotta get that sweet 30% cut!
- internalthief 7y agoI doubt that this is going to be an issue for applications using ReactNative or other solutions to package websites as applications. For applications that have you add it to your home screen using the app icon, it may be more of an issue, but why wouldn't you sync that data back up to the server?
- jessaustin 7y agoYes of course if you're running a business then you're getting users logged in ASAP. There are other models of software development, however. Even if you're in the commercial sector, some users may be less eager than others to sign up for your fine service. Should you preemptively suck in their data, whoops I mean back up their data, without telling them? It seems there could be several responses to that question... It's fine that Apple don't want to support this valid mode of app distribution and use. It is a valid mode, however.
- matsemann 7y agoJust FYI (If I'm reading you correctly): That's not how react native works. It's a native app, not a wrapped website.
- CodeCube 7y agoI suspect they just meant regular react
- 867-5309 7y agoso what is the modern version of PhoneGap?
- WorldMaker 7y agoIonic Capacitor
- pengstrom 7y agoCordova?
- dfabulich 7y agoThat is what it means. The only workaround is to require the user to login and to keep a backup of the data on your server.
- dillondoyle 7y agoThis is what we do. Store a 1st party httponly secure cookie jwt representing the user, then grab any extra data from the backend. Or just something like session cookie but persist it. I wouldn't be surprised if this is one of the ways ad tracking tries to rebuild a universal identifier like the old urchin module. Might not be as easy as a cname but those might get blocked. It's always a game of cat and mouse. Could place uuid as 1st party httponly cookie. maybe uuid is domain scoped. then 'echo out' so accessible by 3rd party JS. Like a hash, one would need to know the global pooled uuid already and then combined with knowable domain could tie that uuid into the 2nd party tracking pool.
- dfabulich 7y ago1st party httponly secure cookies will be erased in seven days. You need the user to manually provide an identifier (i.e. login) to avoid losing everything. The user's password safe is now the only non-volatile storage mechanism on Safari.
- johncolanduoni 7y agoThey explicitly say 1st party httponly secure cookies are exempt and are their first recommended alternative.
- shakna 7y ago> 1st party httponly secure cookies will be erased in seven days. httponly cookies can't be set from JS, and the seven day erasure only applies to cookies set from JS. That's why they're the recommended method for keeping a user logged in.
- tempestn 7y agoExactly. Which to me suggests this could result in more tracking rather than less. At AutoTempest we haven't even bothered to make user accounts thus far, since there's no reason why you should need an account to search for used cars, and we can store user preferences in cookies or localStorage. If those only persist for 7 days though, we're basically forced to have users create accounts and store their preferences on our servers, to avoid a poor user experience. Blocking 3rd party cookies I'm fully on board with, but I don't want first party cookies deleted unless I actually specify it. Fortunately as a user I can keep using Firefox, but since iOS is always going to be a large percentage of our users, there's not much choice on the provider side.
- untog 7y ago> after seven days of Safari use without user interaction on the site If it's a PWA that's regularly used you should be fine. But if not, yeah, that's going to be very annoying.
- cageface 7y agoIf this is really about protecting users and not about kneecapping web apps shouldn't Apple also wipe user data in native apps that haven't been used in a week?
- untog 7y agoNative apps don't really have the problem of third-party ad networks storing data intermixed with app data in this way, though.
- pspeter3 7y agoWhy not though? It seems like third-party SDKs could be included by the developer and stored on my local device.
- cageface 7y agoEvery iOS app I ever built for a client had Facebook's SDK and tracking installed, at the client's request. Often Google's and Twitter's too and the user has no awareness of this.
- detaro 7y agoThe regular reports about tracking in random advertising/... SDKs suggest otherwise
- sroussey 7y agoThey are much worse.
- progval 7y agoOutside privacy issues; visiting a website once shouldn't be enough for a website to store as much data as it wants on someone's computer. Installing a native app is a stronger form of opt-in than simply clicking an URL to a new website.
- doctoboggan 7y agoMy understanding was that yes, if the user doesn't interact with the site in 7 days then the stored data (in cookies and localStorage) will be deleted.
- koolba 7y agoIt’s the usual “this is why we can’t have nice things”. Anything persistent will be turned into a tracking cookie. So eventually everything becomes ephemeral.
- drdaeman 7y agoNot if there's a proper opt-in permission prompt, just like for GPS or camera/microphone access. It's not trivial, though, seeing how notification prompts were abused...
- currysausage 7y agoSites would just instruct users to accept permanent storage in exchange for free content.
- cutemonster 7y agoBut then why don't they already force visitors to accept push notifications?
- infotogivenm 7y agoIt is confusingly worded, but DOES NOT mean all browser storage mechanisms will break. The key phrase is “without user interaction”. Only e.g. invisible nested iframes that scammy ad companies love to use will have their localstorage limits affected. Top level frames are unchanged.
- infotogivenm 7y agoTo be clearer; this is a huge win for privacy/antitracking without any? real downsides. > “chrome will never have this” Indeed :)
- jahewson 7y agoI think you’ve also misread the original text: “seven days of Safari use without user interaction on the site” Does not mean that top-level frames are unaffected. Everybody is affected. They specifically call out first party storage as being misused currently. I think the correct interpretation is: Whenever the user interacts with your page then the clock gets reset to 7 days, also the clock only runs on days the user uses Safari.
- jessaustin 7y agoI hope you're right! Where TFA has: Now ITP has aligned the remaining script-writable storage forms with the existing client-side cookie restriction, deleting all of a website’s script-writable storage after seven days of Safari use without user interaction on the site. ...maybe "script-writable" should be "third-party-in-iframe-script-writable"? If so this document should be edited.
- vbezhenar 7y agoApple have to put restrictions on websites, otherwise users might break free from AppStore walled garden.
- alexcroox 7y agoDon’t they just mean the localstorage containers for other domains than the current one? Ie your normal app’s storage will be left untouched as it is currently but third party domain localstorage containers will be wiped?